
Faculty of Computer Science
University of New Brunswick
550 Windsor Street, ITC314
Fredericton, NB, E3B 5A3
Phone: 506-453-4901
Fax: 506-453-3566
Completed Project : Alert Correlation
Overview
With the large volume of alerts produced by low-level detectors, management of intrusion alerts is becoming more challenging. Manual analysis of this large number of raw alerts is both time consuming and labor intensive. Alert Correlation addresses this issue by finding similarity and causality relationships between raw alerts to provide a condensed, yet more meaningful view of the network from the intrusion standpoint. Previous learning-based approaches either fail to cope with a large number of generated alerts in a large-scale network or do not address the problem of concept drift directly. Our approach to aggregation provides a reduced view of developed patterns of alerts. At the core of the proposed framework is a new algorithm for mining correlated patterns of single-step attacks.
Related Publications
|